Visible to the public Implementation of Two Factor Authentication (2FA) and Hybrid Encryption to Reduce the Impact of Account Theft on Android-Based Instant Messaging (IM) Applications

TitleImplementation of Two Factor Authentication (2FA) and Hybrid Encryption to Reduce the Impact of Account Theft on Android-Based Instant Messaging (IM) Applications
Publication TypeConference Paper
Year of Publication2020
AuthorsSegoro, M. B., Putro, P. A. Wibowo
Conference Name2020 International Workshop on Big Data and Information Security (IWBIS)
Keywordsaccount theft, AES 128, android, android encryption, authentication, confidential messages, Electronic mail, electronic messaging, Encryption, end-to-end encryption, Fingerprint (5), Fingerprint recognition, Human Behavior, hybrid encryption, Hybrid Encryption (2), implementation designs, Instant messaging, Instant messaging (1), instant messaging application security, message decryption process, message security, Metrics, pubcrawl, public key cryptography, QR Code (4), QR code implementation, QR codes, resilience, Resiliency, RSA 2048, Scalability, security, Servers, Two factor Authentication, two-factor authentication, Two-factor authentication (3)
Abstract

Instant messaging is an application that is widely used to communicate. Based on the wearesocial.com report, three of the five most used social media platforms are chat or instant messaging. Instant messaging was chosen for communication because it has security features in log in using a One Time Password (OTP) code, end-to-end encryption, and even two-factor authentication. However, instant messaging applications still have a vulnerability to account theft. This account theft occurs when the user loses his cellphone. Account theft can happen when a cellphone is locked or not. As a result of this account theft, thieves can read confidential messages and send fake news on behalf of the victim. In this research, instant messaging application security will be applied using hybrid encryption and two-factor authentication, which are made interrelated. Both methods will be implemented in 2 implementation designs. The implementation design is securing login and securing sending and receiving messages. For login security, QR Code implementation is sent via email. In sending and receiving messages, the message decryption process will be carried out when the user is authenticated using a fingerprint. Hybrid encryption as message security uses RSA 2048 and AES 128. Of the ten attempts to steal accounts that have been conducted, it is shown that the implementation design is proven to reduce the impact of account theft.

DOI10.1109/IWBIS50925.2020.9255501
Citation Keysegoro_implementation_2020